@micro-banana
Which Ros version are you running?
The routing-mark in /ip route has been replaced by routing-table in v 7.x.
Also, you posted a partial configuration, there is no way to know if any of the tens of other settings you did NOT post may affect the way the router works (or fails to).
More or less, generally speaking, if you actually knew where the issue is and thus post only the relevant parts of the configuration, you would have already solved it, otherwise the advice is to post the FULL configuration, amonymizing/editing the sensitive parts, see: Forum rules - #5 by gigabyte091
and Rule #12 here: The twelve Rules of Mikrotik Club
The diagram is a good start. Explaining more on the traffic flows is helpful and your goals.
If you have one LAN, what is the goal. Load Balancing (using both ISPs at the same time), or primary and failover?
Do you have services that need to communicate with the router itself ( like any VPN ) and if so, provide description of the requirements.
Are there any users on the LAN that require different traffic flows?
Are there any devices on the LAN that external users need to reach.
Plus as noted before the config is key ( and current version being used).
/export file=anynameyouwish ( minus router serial number, any public WANIP information, keys, dhcp lease lists )
i’m so dumb because of i’m creating the config with read account so i’m trying to get admin prevililege acc and i’ll test it again and i’ll come back with config as you mentions if it was failed. is it relative with user acc creating the mangle rule ?
THose details or requirements should be detailed in order to process the config, especially any outside access………. Forward ports? Servers? Anything to the router itself (VPNs etc. )